WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 51–100 of 29,007 vulnerabilities

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium MPG Plugin Path Traversal Editor+ Arbitrary File Read via Project Import < 4.2.3 Fixed in 4.2.3 CVE-2026-103293 WPScan
6.4 Medium WP Ultimate Review Plugin wp-ultimate-review Cross-Site Scripting Author+ Stored XSS via Review Overview Settings < 2.4.4 Fixed in 2.4.4 CVE-2026-101162 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Denial of Service Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101161 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Denial of Service Unauthenticated DoS via Non-Numeric Review Rating No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101160 WPScan
7.5 High WP Ultimate Review Plugin wp-ultimate-review Cross-Site Scripting Unauthenticated Stored XSS via Review Submission No login needed < 2.4.4 Fixed in 2.4.4 CVE-2026-101159 WPScan
6.1 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation No login needed ≤ 5.5.1.5 CVE-2026-103909 Wordfence
6.1 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Cross-Site Scripting Reflected Cross-Site Scripting via 'woosq-redirect' Parameter No login needed ≤ 4.4.0 CVE-2026-103888 Wordfence
4.9 Medium SEOPress Plugin wp-seopress Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'seopress_google_analytics_matomo_id' Parameter ≤ 10.2 CVE-2026-101357 Wordfence
6.4 Medium Rich Showcase for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API) ≤ 7.1.3 CVE-2026-100148 Wordfence
7.2 High Transliterator Plugin serbian-transliteration Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder No login needed ≤ 2.5.8 CVE-2026-96575 Wordfence
8.1 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter No login needed ≤ 1.2.30 CVE-2026-101923 Wordfence
5.3 Medium WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons Plugin social-icons-widget-by-wpzoom Information Disclosure Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`… No login needed ≤ 4.7.3 CVE-2026-100149 Wordfence
7.2 High Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters No login needed ≤ 2.12.2 CVE-2026-87091 Wordfence
6.5 Medium All in One SEO Plugin all-in-one-seo-pack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter No login needed ≤ 5.0.2 CVE-2026-100152 Wordfence
7.5 High Simple Membership Plugin simple-membership Broken Access Control Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints No login needed ≤ 4.8.3 CVE-2026-97337 Wordfence
6.4 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget ≤ 1.3.2 CVE-2025-12828 Wordfence
7.2 High Magic Tooltips For Contact Form 7 Plugin magic-tooltips-for-contact-form-7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author No login needed ≤ 1.0.34 CVE-2026-101928 Wordfence
7.2 High Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'platform_user_photo' Custom Field No login needed ≤ 3.3.11 CVE-2026-96650 Wordfence
7.2 High SEOPress Plugin wp-seopress Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Author Display Name No login needed ≤ 10.2 CVE-2026-96564 Wordfence
7.5 High GeoDirectory Plugin geodirectory SQL Injection Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing No login needed ≤ 2.8.186 CVE-2026-103913 Wordfence
7.2 High Visitor Traffic Real Time Statistics Plugin visitors-traffic-real-time-statistics Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header No login needed ≤ 8.16 CVE-2026-97341 Wordfence
7.2 High GD Rating System Plugin gd-rating-system Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX No login needed ≤ 3.7.1 CVE-2026-93430 Wordfence
6.4 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write ≤ 3.2.1 CVE-2026-97344 Wordfence
4.3 Medium Alt Text AI Plugin alttext-ai Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Content Modification via atai_enrich_post_content AJAX Action ≤ 1.10.41 CVE-2026-91108 Wordfence
4.3 Medium Helpdesk Support Ticket System for WooCommerce Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter ≤ 2.1.6 CVE-2026-11399 Wordfence
6.4 Medium EmbedPress Plugin embedpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute ≤ 4.6.6 CVE-2026-92727 Wordfence
6.1 Medium LearnPress Plugin learnpress Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 'orderby' Parameter No login needed ≤ 4.4.7 CVE-2026-92538 Wordfence
8.8 High Groundhogg Plugin groundhogg Privilege Escalation Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test ≤ 4.9 CVE-2026-97644 Wordfence
7.2 High Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 5.3.5 CVE-2026-92977 Wordfence
6.1 Medium EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI Parameter Key No login needed ≤ 8.7.7 CVE-2026-92826 Wordfence
6.1 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Cross-Site Scripting Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter No login needed ≤ 4.17.4 CVE-2026-92551 Wordfence
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields ≤ 4.17.4 CVE-2026-92536 Wordfence
7.5 High Ultimate Member Plugin ultimate-member Broken Access Control Missing Authorization to Unauthenticated Sensitive Profile Field Disclosure via Member Directory Field Privacy Bypass No login needed ≤ 2.13.1 CVE-2026-93428 Wordfence
6.5 Medium SupportCandy Plugin supportcandy SQL Injection Authenticated (Custom+) SQL Injection via 'sort_by' Parameter ≤ 3.5.3 CVE-2026-94539 Wordfence
6.4 Medium SupportCandy Plugin supportcandy Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'name' Parameter ≤ 3.5.3 CVE-2026-94378 Wordfence
6.1 Medium Ivory Search Plugin add-search-to-menu Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 's' Parameter No login needed ≤ 5.5.18 CVE-2026-92243 Wordfence
5.4 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 3.2.19 CVE-2026-100180 Wordfence
7.2 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'form_id' Parameter No login needed ≤ 2.13.1 CVE-2026-96270 Wordfence
6.5 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version SQL Injection Authenticated (Contributor+) SQL Injection via 'fields[][value]' Parameter ≤ 2.11.0.5 CVE-2026-95865 Wordfence
8.8 High Wallstreet Plugin wallstreet Cross-Site Request Forgery No login needed ≤ 2.8.6 CVE-2026-39718 Patchstack
7.5 High CodeArt Google MP3 Audio Player Plugin google-mp3-audio-player Path Traversal CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_download.php No login needed ≤ 1.0.11 CVE-2014-125130 VulnCheck
6.5 Medium All in One SEO Plugin all-in-one-seo-pack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Search Query No login needed < 5.0.2.1 Fixed in 5.0.2.1 CVE-2026-19856 WPScan
4.3 Medium LearnPress Plugin learnpress Broken Access Control ≤ 4.4.9.1 CVE-2026-39717 Patchstack
3.7 Low Booking Calendar Plugin booking Other Race Condition No login needed ≤ 11.8.4 CVE-2026-39601 Patchstack
4.7 Medium Aculect AI Companion Plugin aculect-ai-companion Open Redirect Unvalidated Redirects and Forwards No login needed ≤ 0.8.1 CVE-2026-39600 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-39444 Patchstack
6.5 Medium WebSamurai Plugin websamurai Broken Access Control ≤ 1.0.7 CVE-2026-39439 Patchstack
6.5 Medium Airano MCP Bridge Plugin airano-mcp-bridge Broken Access Control ≤ 2.11.0 CVE-2026-32585 Patchstack
5.3 Medium Smart One Click Setup – Complete Demo Import & Export Plugin smart-one-click-setup Information Disclosure Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure No login needed ≤ 1.4.3 CVE-2026-32584 Patchstack
7.2 High JetAppointment Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter No login needed ≤ 2.5.2.1 CVE-2026-93875 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only